Uploaded image for project: 'PUBLIC - Liferay Portal Community Edition'
  1. PUBLIC - Liferay Portal Community Edition
  2. LPS-14127

Add new category in message board stores password in plain text in database

    Details

    • Branch Version/s:
      6.0.x, 5.2.x

      Description

      Steps to reproduce the problem:

      1. Login to liferay, click remember password in Firefox
      2. Create new category in Message Board - without activating Mailing List
      3. Check table mbmaiinglist, the fields insusername and inpassword are filled with the
      user credentials. Password is saved in plaintext!

      I added disabled="true" to field="inPassword" in html/portlet/message_boards/edit_category.jsp,
      that seems to fix the issue.

        Attachments

          Activity

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Days since last comment:
                7 years, 11 weeks ago

                Packages

                Version Package
                --Sprint 12/11
                6.1.0 CE RC1